
Import Products, Variations and Attributes – Free by WP Masters Security & Risk Analysis
wordpress.org/plugins/import-products-variations-and-attributes-free-by-wp-mastersNow you can import XLSX to WooCommerce and get Products Variations and Attributes created automatically!
Is Import Products, Variations and Attributes – Free by WP Masters Safe to Use in 2026?
Generally Safe
Score 85/100Import Products, Variations and Attributes – Free by WP Masters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "import-products-variations-and-attributes-free-by-wp-masters" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all outputs, indicating a strong defense against common injection and XSS vulnerabilities. Furthermore, the absence of known CVEs and a clean vulnerability history suggest a generally well-maintained codebase. The plugin also avoids file operations and external HTTP requests, which reduces potential attack vectors.
However, a significant concern arises from its attack surface. The analysis reveals one AJAX handler that lacks authentication checks, presenting a clear security risk. While the taint analysis did not identify critical or high-severity unsanitized paths, the presence of two flows with unsanitized paths, even if not classified as critical, warrants attention. The complete absence of nonce checks on the AJAX handler is a missed opportunity for robust security, allowing for potential Cross-Site Request Forgery (CSRF) attacks or unauthorized actions if an attacker can trigger this handler.
In conclusion, while the plugin excels in data sanitization and query handling, the unprotected AJAX endpoint is a critical weakness that could be exploited. The vulnerability history is reassuring, but it doesn't negate the immediate risk posed by the current code. Addressing the unauthenticated AJAX handler is paramount to improving the plugin's security.
Key Concerns
- AJAX handler without authentication check
- Missing nonce checks on AJAX handler
- Flows with unsanitized paths detected
Import Products, Variations and Attributes – Free by WP Masters Security Vulnerabilities
Import Products, Variations and Attributes – Free by WP Masters Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Import Products, Variations and Attributes – Free by WP Masters Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Import Products, Variations and Attributes – Free by WP Masters Maintenance & Trust
Maintenance Signals
Community Trust
Import Products, Variations and Attributes – Free by WP Masters Alternatives
WP All Import – Product Import for WooCommerce
woocommerce-xml-csv-product-import
Drag & drop to import products from any CSV, XML, Excel, or Google Sheets file. Supports variations, images, attributes, brands, and more with pow …
Product Excel Import & Export for WooCommerce
woo-product-excel-importer
WordPress Plugin to Import Products and Export Products for Woocommerce in Bulk with Excel.
Dropshipping XML for WooCommerce
dropshipping-xml-for-woocommerce
Import products from CSV or XML product feeds to WooCommerce. WooCommerce dropshipping plugin to import wholesale products, update and synchronize the …
Import Products and Handle Orders
doubridge
import products to your store and handle orders for you. Don't worry about inventory,packing etc.just focus on boosting sales and local service
Current RMS Import
import-current-rms
Import from Current RMS(Rental Management System) to Woocommerce products using API.
Import Products, Variations and Attributes – Free by WP Masters Developer Profile
7 plugins · 1K total installs
How We Detect Import Products, Variations and Attributes – Free by WP Masters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-products-variations-attributes-free-by-wp-masters/assets/css/custom-style.css/wp-content/plugins/import-products-variations-attributes-free-by-wp-masters/assets/js/custom-script.js/wp-content/plugins/import-products-variations-attributes-free-by-wp-masters/assets/js/custom-script.js/wp-content/plugins/import-products-variations-attributes-free-by-wp-masters/assets/css/custom-style.css?ver=/wp-content/plugins/import-products-variations-attributes-free-by-wp-masters/assets/js/custom-script.js?ver=HTML / DOM Fingerprints
wpm-variation-import-wrapWPM_VariationsImportwpm_import_variations_ajax_object